<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic As you mentioned &amp;quot;hair in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767896#M177608</link>
    <description>&lt;P&gt;As you mentioned "hair-pinning" so can you explain the required traffic flow in your setup.&lt;/P&gt;&lt;P&gt;Explain with example so that we can easily understand the requirement and help you in implementing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2015 08:36:09 GMT</pubDate>
    <dc:creator>Rishabh Seth</dc:creator>
    <dc:date>2015-10-19T08:36:09Z</dc:date>
    <item>
      <title>Same VLAN Traffic Blocking</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767891#M177603</link>
      <description>&lt;P&gt;Hi Friends,&lt;/P&gt;&lt;P&gt;I have Cisco ASA 5545-x firewall.I have configured all the VLAN's in firewall.When We are trying connect the same VLAN server(any tcp or udp ports )the traffic coming to firewall and getting block.I have already enabled same-security infra-interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me to resolve this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mathew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:46:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767891#M177603</guid>
      <dc:creator>shinumathew123</dc:creator>
      <dc:date>2019-03-12T06:46:01Z</dc:date>
    </item>
    <item>
      <title>Hi, Can you explain the</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767892#M177604</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you explain the network setup and provide details about the required traffic flow in your network.&lt;/P&gt;&lt;P&gt;Also let us know if the machine from where you are trying to connect to the server are in the same vlan or different?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Share your findings,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 07:34:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767892#M177604</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-19T07:34:48Z</dc:date>
    </item>
    <item>
      <title>HI Seth,Yes .The servers are</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767893#M177605</link>
      <description>&lt;P&gt;HI Seth,&lt;/P&gt;&lt;P&gt;Yes .The servers are in same vlan.&lt;/P&gt;&lt;P&gt;1. Created all the vlans in the firewall&lt;/P&gt;&lt;P&gt;2. Created sub-interfaces&lt;/P&gt;&lt;P&gt;3. Servers GW is sub interface ip address&lt;/P&gt;&lt;P&gt;Server A(10.10.10.100) trying to connect Server B(10.10.10.101)&lt;/P&gt;&lt;P&gt;Attached the diagram for better understanding.I have already enabled same-security infra-interface.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mathew&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 08:07:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767893#M177605</guid>
      <dc:creator>shinumathew123</dc:creator>
      <dc:date>2015-10-19T08:07:17Z</dc:date>
    </item>
    <item>
      <title>Hi Mathew, I understand that</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767894#M177606</link>
      <description>&lt;P&gt;Hi Mathew,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I understand that the servers are in same VLAN and you have permitted intra-interface traffic.&lt;/P&gt;&lt;P&gt;But the client are also in the same vlan?&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;nbsp;If you are trying to test connectivity between serverA and serverB then, the ASA will not come into picture as the two servers are in the same subnet so they will communicate directly.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; If the client is behind a different interface then you should check ACLs and permit traffic.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; If ASA is doing inter-vlan routing (like router on stick) then enable inter-interface traffic as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let us know if this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;Mark the answer as correct if it helps in resolving your query!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 08:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767894#M177606</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-19T08:14:08Z</dc:date>
    </item>
    <item>
      <title>Hi Seth,Yes.Right. Both are</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767895#M177607</link>
      <description>&lt;P&gt;Hi Seth,&lt;/P&gt;&lt;P&gt;Yes.Right. Both are same VLAN.The traffic wont come to the firewall.Its very weird .I am seeing the traffic in the firewall.Is it some thing related to hair pinning. Need to add some NAT here.&lt;/P&gt;&lt;P&gt;I just confused.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 08:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767895#M177607</guid>
      <dc:creator>shinumathew123</dc:creator>
      <dc:date>2015-10-19T08:32:08Z</dc:date>
    </item>
    <item>
      <title>As you mentioned "hair</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767896#M177608</link>
      <description>&lt;P&gt;As you mentioned "hair-pinning" so can you explain the required traffic flow in your setup.&lt;/P&gt;&lt;P&gt;Explain with example so that we can easily understand the requirement and help you in implementing it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 08:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767896#M177608</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-19T08:36:09Z</dc:date>
    </item>
    <item>
      <title>One more thing .As you said</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767897#M177609</link>
      <description>&lt;P&gt;One more thing .As you said.If both are in same network .Traffic wont go to firewall.I have checked the ARP table in the switch .Their are no ARP entiry.All the ARP entry is in firewall only.&lt;/P&gt;&lt;P&gt;See this video for Hair pinning&lt;/P&gt;&lt;P&gt;https://www.youtube.com/watch?v=wjEfdfI0BqY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 08:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767897#M177609</guid>
      <dc:creator>shinumathew123</dc:creator>
      <dc:date>2015-10-19T08:41:23Z</dc:date>
    </item>
    <item>
      <title>Hi Matt, Are you trying to</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767898#M177610</link>
      <description>&lt;P&gt;Hi Matt,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you trying to access the server on its public IP or on its private IP?&lt;/P&gt;&lt;P&gt;If its the public IP then the ASA will be processing the traffic otherwise the client will directly contact the server on its private IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In case you are using public IP then check your NAT rule on ASA.&lt;/P&gt;&lt;P&gt;Also, you should check arp table on the end clients and not the switch. On switch you can check the mac address&amp;nbsp;table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 08:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767898#M177610</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-19T08:50:39Z</dc:date>
    </item>
    <item>
      <title>Hi Seth,I have already</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767899#M177611</link>
      <description>&lt;P&gt;Hi Seth,&lt;/P&gt;&lt;P&gt;I have already explained the traffic flow. Both are in same network servers.I am trying to access internally and both connected in same switch.No other client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 08:55:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767899#M177611</guid>
      <dc:creator>shinumathew123</dc:creator>
      <dc:date>2015-10-19T08:55:45Z</dc:date>
    </item>
    <item>
      <title>Hi Matt, If you are trying to</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767900#M177612</link>
      <description>&lt;P&gt;Hi Matt,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are trying to access server A from server B on its internal IP then you should be able to reach the application without passing trough ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; Try to check reachability by pinging devices.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; If you have reachability then check if there is any firewall/ setting that might be blocking the traffic.&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt; Also check the arp on the client and server and confirm you see correct MAC-IP mapping.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 09:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767900#M177612</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-19T09:24:47Z</dc:date>
    </item>
    <item>
      <title>Yes.The funny part is the</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767901#M177613</link>
      <description>&lt;P&gt;Yes.The funny part is the first ping got filtered&amp;nbsp; and reaching that packets&amp;nbsp; to firewall.Rest of the packets are passing and if I allow the ports in the firewall it works.But Why the packets are coming to firewall.thats my concern.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 09:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767901#M177613</guid>
      <dc:creator>shinumathew123</dc:creator>
      <dc:date>2015-10-19T09:37:28Z</dc:date>
    </item>
    <item>
      <title>Do you have any static NAT</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767902#M177614</link>
      <description>&lt;P&gt;Do you have any static NAT configured on ASA for the internal subnet IP?&lt;/P&gt;&lt;P&gt;If yes then try to edit the NAT and apply no-proxy-arp in that NAT rule and check if it helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 09:54:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767902#M177614</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-19T09:54:56Z</dc:date>
    </item>
    <item>
      <title>No.I do not have any static</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767903#M177615</link>
      <description>&lt;P&gt;No.I do not have any static NAT configured&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 15:52:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767903#M177615</guid>
      <dc:creator>shinumathew123</dc:creator>
      <dc:date>2015-10-19T15:52:20Z</dc:date>
    </item>
    <item>
      <title>Are you using IP address /</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767904#M177616</link>
      <description>&lt;P&gt;Are you using IP address / domain to access the web server?&lt;/P&gt;&lt;P&gt;If it is domain name, check the DNS resolution, is it public IP or private IP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you have described the setup, the traffic should not come to ASA unless you are using Public IP.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 17:30:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767904#M177616</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-19T17:30:25Z</dc:date>
    </item>
    <item>
      <title>No .Its application servers.</title>
      <link>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767905#M177617</link>
      <description>&lt;P&gt;No .Its application servers. There is no public ip address in picture.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 17:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/same-vlan-traffic-blocking/m-p/2767905#M177617</guid>
      <dc:creator>shinumathew123</dc:creator>
      <dc:date>2015-10-19T17:44:31Z</dc:date>
    </item>
  </channel>
</rss>

